2 дня назад
Incident Response Specialist Cybersecurity Ops Analyst
52 320 - 70 787€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Incident Response Specialist Cybersecurity Ops Analyst (Cybersecurity/DFIR): Building and operating incident response services for Amgen's global enterprise with an accent on advanced endpoint, network, cloud, and identity investigations. Focus on threat hunting, digital evidence analysis, detection content, response automation, and containment and recovery of complex cyber incidents.
Location: Lisbon, Portugal
Salary: €52,320.90–€70,787.10 per year
Company
is a biotechnology and healthcare company whose Portugal Capability Center supports global operations through technology, cybersecurity, research, finance, and other functions.
What you will do
- Execute all phases of the incident response lifecycle, from preparation and identification through containment, eradication, recovery, and post-incident review.
- Investigate endpoint, network, cloud, identity, email, and system security incidents across enterprise environments.
- Analyze SIEM, EDR/XDR, NDR, cloud security, and threat intelligence data to scope incidents and reconstruct attack timelines.
- Conduct enterprise-wide threat hunting using IOCs, IOAs, behavioral analytics, and the MITRE ATT&CK framework.
- Acquire and preserve digital evidence, perform forensic analysis, and document findings, root causes, attack timelines, and lessons learned.
- Develop detection content, scripting, automation, playbooks, and response workflows while collaborating with cybersecurity and SOAR engineering teams.
Requirements
- At least five years of directly related incident response experience.
- Practical DFIR experience across host, network, cloud environments such as AWS, GCP, and Azure, and operational technology.
- Knowledge of security controls including firewalls, intrusion detection, anti-malware, secure gateways, security monitoring, and encryption.
- Experience with tools such as CrowdStrike, QRadar, EnCase, Office 365 Security, and log and endpoint analysis platforms.
- Knowledge of TCP/IP, information security standards including ISO 27001/27002 and NIST, and regulated systems such as GxP and SOX.
- Strong analytical, communication, coordination, collaboration, and problem-solving skills with the ability to work under minimal supervision.
Nice to have
- Experience supporting incident response for a multinational organization and working with Agile principles.
- Experience in pharmaceutical, biotechnology, or healthcare environments.
- Certifications such as CISSP, GNFA, GCIH, GCFE, GCFA, GRID, CompTIA CySA+, or AWS Security Specialty.
Culture & Benefits
- Work within a global team representing more than 40 nationalities.
- Support ’s mission to serve patients through cybersecurity services and projects.
- Work from the Capability Center office in Lisbon.
- Collaborate with Threat Intelligence, Security Engineering, Cloud Security, Identity, Network Security, Endpoint Security, and other teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
20 часов назад
Security Engineer - Incident Response (Cybersecurity)
70 000 - 107 800€
7 дней назад
Security Engineer (AI)
61 000 - 76 000€
6 дней назад
Security Engineer (AI)
61 000 - 76 000€
4 дня назад
Security Operations Manager - Assistant Vice President (Cybersecurity)
2 дня назад
Network Security Engineer
38 000 - 52 000€
3 дня назад